{"api_version":"1","generated_at":"2026-10-01T22:29:08+00:00","cve":"CVE-2026-90238","urls":{"html":"https://cve.report/CVE-2026-90238","api":"https://cve.report/api/cve/CVE-2026-90238.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-90238","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-90238"},"summary":{"title":"media: amd: isp4: fix self-deadlock in isp4sd_pwron_and_init() error path","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: amd: isp4: fix self-deadlock in isp4sd_pwron_and_init() error path\n\nisp4sd_pwron_and_init() holds ops_mutex via guard(mutex) and, on any\ninit failure, jumps to err_deinit and calls isp4sd_pwroff_and_deinit().\nThat helper takes the same ops_mutex, re-acquiring a non-recursive mutex\nalready held by the current thread, so any init failure deadlocks.\n\nUnwind the error path in stages instead, releasing only what each\nfailure point acquired. This also avoids the issues that an\nunconditional teardown would hit at the earlier failures, such as a\nruntime-PM underflow from pm_runtime_resume_and_get() and MMIO access\nwhile the device is unpowered.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-09-17 17:17:19","updated_at":"2026-09-17 17:17:19"},"problem_types":[],"metrics":[],"references":[{"url":"https://git.kernel.org/stable/c/74669cc3483e9729ca26b4e06a096ccdd607db64","name":"https://git.kernel.org/stable/c/74669cc3483e9729ca26b4e06a096ccdd607db64","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/ef46d80a7015269a98c9505b5912a83798799199","name":"https://git.kernel.org/stable/c/ef46d80a7015269a98c9505b5912a83798799199","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-90238","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-90238","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 4e5e7a7ddb4ab9ac35928d7dc72efc8797639dc3 74669cc3483e9729ca26b4e06a096ccdd607db64 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 4e5e7a7ddb4ab9ac35928d7dc72efc8797639dc3 ef46d80a7015269a98c9505b5912a83798799199 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 7.2","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2.6 7.2.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.3-rc1 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["drivers/media/platform/amd/isp4/isp4_subdev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"74669cc3483e9729ca26b4e06a096ccdd607db64","status":"affected","version":"4e5e7a7ddb4ab9ac35928d7dc72efc8797639dc3","versionType":"git"},{"lessThan":"ef46d80a7015269a98c9505b5912a83798799199","status":"affected","version":"4e5e7a7ddb4ab9ac35928d7dc72efc8797639dc3","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["drivers/media/platform/amd/isp4/isp4_subdev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"7.2"},{"lessThan":"7.2","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"7.2.*","status":"unaffected","version":"7.2.6","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.3-rc1","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2.6","versionStartIncluding":"7.2","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.3-rc1","versionStartIncluding":"7.2","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: amd: isp4: fix self-deadlock in isp4sd_pwron_and_init() error path\n\nisp4sd_pwron_and_init() holds ops_mutex via guard(mutex) and, on any\ninit failure, jumps to err_deinit and calls isp4sd_pwroff_and_deinit().\nThat helper takes the same ops_mutex, re-acquiring a non-recursive mutex\nalready held by the current thread, so any init failure deadlocks.\n\nUnwind the error path in stages instead, releasing only what each\nfailure point acquired. This also avoids the issues that an\nunconditional teardown would hit at the earlier failures, such as a\nruntime-PM underflow from pm_runtime_resume_and_get() and MMIO access\nwhile the device is unpowered."}],"providerMetadata":{"dateUpdated":"2026-09-17T16:07:43.159Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/74669cc3483e9729ca26b4e06a096ccdd607db64"},{"url":"https://git.kernel.org/stable/c/ef46d80a7015269a98c9505b5912a83798799199"}],"title":"media: amd: isp4: fix self-deadlock in isp4sd_pwron_and_init() error path","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-90238","datePublished":"2026-09-17T16:07:43.159Z","dateReserved":"2026-09-11T19:38:34.794Z","dateUpdated":"2026-09-17T16:07:43.159Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-17 17:17:19","lastModifiedDate":"2026-09-17 17:17:19","problem_types":[],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"90238","Ordinal":"1","Title":"media: amd: isp4: fix self-deadlock in isp4sd_pwron_and_init() e","CVE":"CVE-2026-90238","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"90238","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: amd: isp4: fix self-deadlock in isp4sd_pwron_and_init() error path\n\nisp4sd_pwron_and_init() holds ops_mutex via guard(mutex) and, on any\ninit failure, jumps to err_deinit and calls isp4sd_pwroff_and_deinit().\nThat helper takes the same ops_mutex, re-acquiring a non-recursive mutex\nalready held by the current thread, so any init failure deadlocks.\n\nUnwind the error path in stages instead, releasing only what each\nfailure point acquired. This also avoids the issues that an\nunconditional teardown would hit at the earlier failures, such as a\nruntime-PM underflow from pm_runtime_resume_and_get() and MMIO access\nwhile the device is unpowered.","Type":"Description","Title":"media: amd: isp4: fix self-deadlock in isp4sd_pwron_and_init() e"}]}}}